LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

detecting-broken-object-property-level-authorization - Detect Broken Object Property Level Authorization

Detects OWASP API3:2023 vulnerabilities involving excessive data exposure and mass assignment in APIs.

Tags

Updated: 2026-09-30

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Detect excessive data exposure
  • Test mass assignment
  • Classify sensitive properties
  • Compare response fields
  • Verify injected changes

Inputs

  • Target API
  • API documentation or schema
  • Authentication headers
  • User accounts
  • API endpoints
  • Expected response fields

Outputs

  • BOPLA findings
  • Vulnerability classifications
  • Sensitive property names
  • API request results
  • Modified API object state

Requirements

  • Python 3.8 or later
  • Python requests library
  • API security testing authorization
  • API endpoints accepting object data
  • Burp Suite or Postman

Source

  • Spec: SKILL.md
api-security
bopla
owasp-api3
mass-assignment
excessive-data-exposure
property-level-authorization
api-testing
penetration-testing
Detect excessive data exposure
Test mass assignment
Classify sensitive properties
Compare response fields
Target API
API documentation or schema
Authentication headers
BOPLA findings
Vulnerability classifications
Sensitive property names